30% of Americans have faced health data breaches this year
qz.com
qz.com
And they even have the audacity to call that Industry standard.
Serious question from someone who takes their privacy seriously. What actual harms have we documented from these breaches?
Mature response. Now actually think about it. If you solve this, you've solved the key barrier to incentivizing change. If you can't answer it, then security seems more like an aesthetic preference than a social problem.
Actual, not hypothetical. Again, I believe this happens. But why is it so difficult to document?
- My old university - T mobile - My health provider
Now if you try to sue any one them regardless of their arbitration mandatory you would have to prove that the harm is because of this particular institution and not the others.
And the notion of identity theft is putting the blame on the people where the actual victims are the banks/dealers and not you. But it is easy to put the responsibility on you.
No, you'd just have to show the first part. That they caused harm.
> the notion of identity theft is putting the blame on the people where thr actual victims are the banks/dealers
This is a real problem. But I haven't seen anyone successfully tie a case of identity theft, even in part, to a particular breach.
These companies have deep buckets and will employee laywers who have experience into squashing all the suits of this kind.
Edit: I have much less faith that your question in the beginning was serious with good intentions now.
Again, this is not true. If two people steal your data, and you can tie the use of any of that stolen data to harm, they are each liable. The problem is in identifying the harms. Not calculating the attributed damage.
> companies have deep buckets and will employee laywers who have experience into squashing all the suits of this kind
A multibillion-dollar payoff for lawyers and a wealthy plaintiff to get a class certified, and the answer is a conspiracy of corporate counsels?
Sure. But why are these database operators' tradecraft so universally solid that nobody can back out attribution, including law enforcement when they search and seize them?
The other stuff, yeah I guess that could hypothetically happen, but how much of a problem was it really and is the cost of HIPAA worth it?
HIPAA, as I have read, was mostly about health insurance portabilty and eliminating things like losing coverage for pre-existing conditions when you changed jobs and insurance. All the privacy regulations were added by the Department of Health and Human Services after the law was passed.
"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one."
That is literally what the entire field exists for. Here's the kicker the cost of X is so monumentally low right now because there are no consequences for it other than firing your CSO (Chief Sacrificial Officer) that there is almost never a reason to issue the recall.
None better though*
* if you make over 500k a year